Medium severity4.3NVD Advisory· Published Jun 4, 2024· Updated Apr 8, 2026
CVE-2024-4274
CVE-2024-4274
Description
The Essential Real Estate plugin for WordPress is vulnerable to unauthorized loss of data due to insufficient validation on the remove_property_attachment_ajax() function in all versions up to, and including, 4.4.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary attachments.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- www.wordfence.com/threat-intel/vulnerabilities/id/7dc41eb7-5c9a-4a67-902d-9a855840668bnvdThird Party Advisory
- plugins.trac.wordpress.org/browser/essential-real-estate/trunk/public/partials/property/class-ere-property.phpnvdProduct
- plugins.trac.wordpress.org/changesetnvd
- plugins.trac.wordpress.org/changesetnvd
News mentions
0No linked articles in our index yet.